Professional Update Management for IoT Device Fleets—From OTA Campaigns to Auditable Fleet Operations

Are you looking for a solution to centrally manage software and security updates across thousands of devices –—including wave deployment, rollback, and audit-ready documentation? Or is your fleet growing, and can you no longer scale onboarding, operations, and compliance manually? Device & Update Management addresses both of these challenges.

Update Management is the core component—supplemented by Device Management, Remote Access, alerting, and compliance—all in an integrated solution—tailored to your device landscape and integration requirements, available as a complete solution or for integration into existing systems.

 

You can centrally manage software and security updates and roll them out in a controlled manner across target groups and waves—using an SSO-enabled web interface, rule-based rollout control, and comprehensive audit trails. The solution can be operated in the cloud, on-premises, or in a hybrid environment—tailored to your IT/OT landscape and compliance requirements.

 

Luca Lutsch portrait
The implementation of the Update Manager has significantly improved our ability to distribute updates efficiently and securely. Thanks to this solution, we can keep all our networked systems up to date globally. This enhances the user experience and security, and improves our product’s performance thanks to new features in the rolled-out software. – Luca Lutsch, Product Owner at ZEISS Microscopy
Background

As the fleet grows, manual processes don't scale with it

Connected device fleets are growing faster than the ability to operate them manually.

Many manufacturers and operators are familiar with this situation:

  • Device status, software versions, and malfunctions are not visible centrally –, making it impossible to get a reliable overview of the fleet.
  • Heterogeneous device types, protocols, and platforms lead to siloed solutions and high integration costs.
  • Provisioning and onboarding are inconsistent—devices are not put into service in a consistent, secure, and scalable manner.
  • Updates cannot be rolled out in a targeted, phased manner with rollback capabilities; dependencies and rollout windows increase the risk of downtime.
  • Remote maintenance is unreliable or not logged—On-site visits remain expensive.
  • Thresholds, outages, and security incidents are detected too late; rule-based escalations are lacking.
  • No comprehensive overview of software in the field—Vulnerability management and CRA-compliant documentation are virtually impossible.
  • Evidence for CRA and NIS2—Patches, accesses, and software versions—are incomplete or cannot be audited.


The result: rising operating costs, growing compliance gaps, increased cyber risks in the field, and a reactive approach instead of predictable fleet operations.

The Solution

An Integrated Solution –
Focus on Update Management

The focus is on update management: OTA campaigns with a phased rollout strategy, target group control, rollback, and auditable history. Around this core, Device & Update Management brings together everything needed for secure fleet operations—inventory and onboarding, remote access, alerting, and compliance throughout the device lifecycle.

Instead of building custom solutions from scratch, doubleSlash and you can rely on proven solution components and tested reference architectures from industrial projects –—tailored to your device landscape and integrable with ThingWorx, Azure IoT, AWS IoT, Mender.io, and other systems. Mender.io can serve as the update backend for the fleet: doubleSlash orchestrates and controls updates via the central interface—and integrates Mender rather than replacing it in existing deployments.


Typical Process in Practice:

  1. Securely onboard devices and manage them in the inventory.
  2. Roll out software and security updates via OTA—in waves, with rollback capabilities and a documented history.
  3. Monitor the fleet, detect issues early, and provide controlled remote support as needed.
  4. Ensure that operations and changes are traceable for audits and compliance.

No devices connected yet? Device Connectivity is the first step.

Benefits

What You Can Win

Shorter time to patch:

Automated OTA campaigns replace weeks of manual, individual maintenance. Security updates can be rolled out across the fleet in defined waves—instead of updating each device individually on-site. At ZEISS Microscopy, this approach is used to centrally update more than 5,000 microscopes worldwide.

 

Fewer on-site visits:

Faster troubleshooting through remote support and targeted alerts—shorter mean time to repair. In established remote service setups, most on-site visits for purely software- and configuration-related issues are often eliminated.

 

Choose your deployment model flexibly:

Cloud, on-premises, or hybrid—– the architecture is tailored to your requirements for data sovereignty, latency, and compliance, not to a fixed deployment model.

Transparency:

Centralized view of device and software versions, campaign status, and risks across the fleet—Standardization instead of scattered, individual solutions.

 

Compliance:

Coordinated delivery of updates and documented evidence for the CRA –, including support for reporting and documentation requirements as part of the process setup.

 

Security by Design:

Logging, role and permission models, encryption, signature verification, and patch management as standard features—not as an after-the-fact fix.

 

Speed:

Proven solution components and tested reference architectures instead of custom development from scratch—enable reliable operations to be achieved more quickly.

Features

What Device & Update Management Does

Update management is at the core—the other areas are what make secure, scalable fleet operations feasible in the first place. Depending on the initial situation and requirements, we combine the relevant components—not every project needs all the features right from the start.

Complete or integrated

Two Approaches to Implementation

Same Objective, Different Levels of Integration

Both approaches serve as entry points for a shared, customized implementation of—not fixed product packages.

The specific features (Update Management, Device Management, Remote Access, Alerting, Compliance) to be implemented are determined during the needs assessment.

Instead of developing everything from scratch, we provide proven solution components and tested reference architectures from industry projects featuring—for OTA campaigns, fleet operations, remote access, and compliance.


What works is adopted. What doesn’t work is adapted.

 

Comprehensive Solution

Together, we’ll build your device and update management solution—using proven solution components and reference architectures as a foundation, tailored to your device landscape, your processes, and your compliance requirements.

Request

Integration with Existing Systems

Are you already using IoT platforms, update systems, or remote access tools? We integrate and orchestrate—using ready-made connectors and proven integration patterns, without replacing what’s already working.

Request

CRA and NIS2:
Ensuring Updates Are Traceable

The Cyber Resilience Act requires manufacturers of connected products to provide regular security updates and document them. NIS2 adds requirements regarding security processes and evidence management. Without a centralized inventory, controllable OTA processes, and logged remote access, these requirements cannot be met in a practical manner in the field.

Device & Update Management addresses this through coordinated update rollouts, comprehensive documentation, transparency regarding software versions, and reporting artifacts for audits. doubleSlash provides technical and organizational implementation support—not legal advice on a case-by-case basis.

Post-Market Surveillance

Classify incidents in the field and resolve them in a verifiable manner

Post-market surveillance requires reliable device data—and the ability to quickly identify affected devices, software versions, and corrective actions. This is particularly relevant in medical technology (MDR) and in mechanical and plant engineering (ISO-based quality and risk management systems).

Manufacturers of connected products must systematically monitor devices after they enter the market: collect reports and signals from the field, classify incidents, determine the causes, and implement corrective actions in a transparent manner.


Device & Update Management provides the technical foundation for this process:

  1. Field Observation 
    Centrally manage inventory, status, and software versions—which devices and versions are on the market.
  2. Incident Logging and Alerts 
    Detect malfunctions, threshold violations, and notifications early through monitoring and alerting.
  3. Technical and Regulatory Classification 
    Investigate and classify incidents using device history, configuration, and remote access –—the basis for determining criticality and next steps.
  1. Traceability and Correction 
    Identify affected devices and versions; roll out security and functional updates as a controlled OTA campaign—including waves, rollbacks, and documented history.
  2. Verification and Improvement 
    Audit trails and reporting for CAPA, audits, and continuous improvement—compatible with existing QMS and compliance processes.

In this way, post-market surveillance does not become merely a matter of retrospective documentation, but rather an end-to-end operational process –—from field monitoring to verifiable corrective action.

Questions & Answers

Fundamentals and Classification

Problem, Benefits, and Relevance


Features, Technology, and Operation


Implementation and Collaboration


Compliance and Regulation

Request a Demo and Consultation